Privacy & Cookie Policy
How Prism Integrated Security Solutions Ltd collects, uses, retains and protects your personal data — and the rights you have over it.
Last updated: 23 August 2026
This notice explains how Prism Integrated Security Solutions Ltd (“Prism”, “we”, “us”) collects, uses, stores and shares personal data, and the rights available to you. It is provided under Articles 13 and 14 of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. Our use of cookies is additionally governed by the Privacy and Electronic Communications Regulations 2003 (PECR).
It applies to:
- visitors to this website, including anyone using our online system builders or booking a survey
- people who contact us by telephone, email or through our enquiry forms
- customers who engage us to install, maintain or monitor security or MediCare systems, and users of our customer portal
- keyholders and contacts registered on alarm monitoring accounts
1. Who we are
The data controller — the organisation responsible for deciding how your personal data is used — is Prism Integrated Security Solutions Ltd, registered office 71–75 Shelton Street, Covent Garden, London, WC2H 9JQ.
We are registered with the Information Commissioner’s Office (ICO) under reference ZC183779. You can verify registered data controllers on the ICO register.
For anything in this notice, or to exercise any of your rights, contact our data protection contact at dpo@prismintegratedsecurity.solutions, call 0330 236 8191, or write to the registered office above. You can also use the form on our contact page.
2. The personal data we collect
We collect only the data needed for a specific, stated purpose. What we hold depends on your relationship with us.
Enquiries and contact forms
- Identity and contact data — your name, email address and phone number
- Company name and postcode, where you provide them
- The content of your message, and your marketing preference (an unticked opt-in box)
Online system builders
If you design a system with our alarm or MediCare builder, we collect your contact details, the installation address, and the property details you enter — floors, rooms, doors and windows — because they are the design. For business customers we also look up and store your company’s registered name, number and registered office from the Companies House public register, so your quotation names the right legal entity.
Health information (special category data)
The MediCare builder includes a free-text notes field where you may choose to tell us about health considerations — for example, that the person the system is for is at risk of falls. This is special category data under Article 9 UK GDPR. We process it only with your explicit consent, which you give by choosing to write it, and we use it solely to design and deliver a suitable system. Share only what you are comfortable sharing — the builder works without it — and you can ask us to delete these notes at any time by contacting dpo@prismintegratedsecurity.solutions.
Survey bookings
When you book a survey we collect your name, contact details, the site address and your chosen appointment slot. If you give us a mobile number we send booking confirmations and appointment reminders by text message. These are service messages, not marketing.
Customers
- Contract and service data — quotations, contracts, invoices, installed systems and equipment, certificates, maintenance history and engineer visit notes
- Site data — installation addresses and, for monitored systems, access details, zone descriptions and response procedures
- Keyholder data — names, phone numbers and call priorities for the keyholders you nominate on a monitoring account
- Payment data — we invoice for payment by bank transfer, so we see the payer name and reference on incoming payments. We do not collect or store card numbers.
If you nominate keyholders, you must make sure those people know their details will be shared with our monitoring partner for alarm response. Point them to this notice.
Customer portal accounts
Portal accounts hold your sign-in email address, your sign-in history, and the documents we have issued to you — quotations, invoices and certificates.
Signing your contract electronically
When you sign a Job Specification from the link we email you, we record your name, the capacity you sign in (for example home owner or director), your drawn signature, the date and time, and the technical details of the signing session — the IP address the request came from, your browser’s identifying string, and a one-off signing reference generated in your browser. These form part of the contract record: they are the evidence that the signature was given, our lawful basis for them is the contract itself, and we keep them for as long as we keep the signed contract.
Technical data
Our hosting infrastructure records standard server logs (IP address, browser type, pages requested) which we use for security and fault diagnosis. Our website analytics are aggregate and cookie-free — see the cookies section below.
3. Why we use it, and our lawful bases
Under Article 6 UK GDPR we must have a lawful basis for every use of personal data. These are ours:
| What we do | Lawful basis |
|---|---|
| Respond to enquiries, prepare quotations and arrange surveys | Legitimate interests — Article 6(1)(f): responding to people who ask us to |
| Design, install, commission, maintain and repair your system; run your portal account | Contract — Article 6(1)(b) |
| Share keyholder and site data with our Alarm Receiving Centre for 24/7 monitoring | Contract — Article 6(1)(b): integral to the monitoring service |
| Send service messages — booking confirmations, appointment reminders, maintenance reminders, renewal notices | Contract and legitimate interests — Articles 6(1)(b) and 6(1)(f) |
| Process health notes you volunteer in the MediCare builder | Explicit consent — Articles 6(1)(a) and 9(2)(a) |
| Keep accounting, tax and contractual records | Legal obligation — Article 6(1)(c): Companies Act 2006, HMRC requirements |
| Email marketing to existing customers about similar services | Legitimate interests — Article 6(1)(f), with the PECR Regulation 22 soft opt-in; every message includes an opt-out |
| Email marketing where you ticked the opt-in box on an enquiry | Consent — Article 6(1)(a) and PECR Regulation 22 |
| Secure our systems, prevent fraud, and establish or defend legal claims | Legitimate interests — Article 6(1)(f) |
| Respond to legal, regulatory or law-enforcement requests | Legal obligation — Article 6(1)(c) |
Where we rely on legitimate interests we have balanced our interests against your rights and freedoms. You can object to any processing based on legitimate interests — see your rights below. You can stop marketing at any time using the unsubscribe link in any marketing email or by contacting us; opting out never affects service messages about work you have asked us to do.
4. Who we share it with
We do not sell, rent or trade personal data — to anyone, ever. We share it only where necessary, under written contracts that meet Article 28 UK GDPR.
Alarm monitoring — EMCS
Monitored systems are connected to EMCS (East Midlands Central Station Limited), the UK’s largest independent Alarm Receiving Centre, NSI Gold certified. EMCS processes keyholder and alarm event data as our data processor, under a written data processing agreement, only on our instruction and only to provide monitoring and response.
Service providers
- Supabase — our database, customer sign-in and document storage, hosted on AWS in London (UK)
- Vercel — website hosting and cookie-free, aggregate analytics
- Resend — delivery of the emails we send you
- Twilio — delivery of booking confirmation and reminder text messages
Others
- Vetted subcontracted engineers, who receive only the minimum needed for a specific job — typically the site address and access arrangements — under written confidentiality agreements
- Professional advisers — accountants, solicitors and insurers — where necessary, bound by professional confidentiality
- Police, courts, regulators and other public authorities, where the law requires it; we will tell you unless we are legally prevented from doing so
5. International transfers
Your data is stored in the United Kingdom — our database, documents and sign-in records live in a London data centre. Some of our service providers are US companies, so limited data (for example, an email address on an outgoing email, or a phone number on a text message) may be processed outside the UK. Where that happens we rely on the UK Extension to the EU–US Data Privacy Framework (the UK–US Data Bridge) or the ICO’s International Data Transfer Agreement, as Chapter V UK GDPR requires.
6. How long we keep it
| Category | Retention period | Why |
|---|---|---|
| Enquiry and builder data where no contract follows | 3 years from last contact | Legitimate interests — limitation periods for civil claims |
| Customer contract records — identity, contact, service history, certificates, invoices | 7 years from contract end | Legal obligation — Companies Act 2006, HMRC requirements |
| Alarm monitoring and keyholder data | Duration of the monitoring contract + 3 years | Contract performance; post-contract queries |
| Health notes volunteered in the MediCare builder | Deleted on request; otherwise retained with the related enquiry or contract record | Explicit consent — withdrawable at any time |
| Marketing consent records | Until consent is withdrawn + 3 years | Legal obligation — evidence of valid consent under PECR |
| Complaints, disputes and legal correspondence | 6 years from resolution | Limitation Act 1980 |
| CCTV footage at our own premises | 31 days | Legitimate interests — ICO surveillance guidance |
When a retention period ends, data is securely deleted or anonymised. We may keep data longer where a court order, live legal proceedings or a specific regulatory obligation requires it, and will tell you where that applies.
7. How we protect it
- Encryption in transit for every connection to the website and portal
- Row-level access controls in the database — a portal account can read its own records and nothing else
- Least-privilege staff access, with an append-only audit log recording who changed what
- Documents stored in a private bucket, never on public URLs
8. Automated processing
Our online builders generate a system specification and draft quotation automatically from your answers. A person reviews every quotation before it is sent, and no decision producing legal or similarly significant effects is made about you by automated means alone.
9. Your rights
Under UK GDPR you have the right to:
- Access (Article 15) — request a copy of the personal data we hold about you (a Subject Access Request)
- Rectification (Article 16) — have inaccurate or incomplete data corrected
- Erasure (Article 17) — have data deleted where there is no compelling reason to keep it
- Restriction (Article 18) — limit how we use your data, for example while you contest its accuracy
- Portability (Article 20) — receive data you gave us in a structured, machine-readable format, where processing is based on consent or contract
- Objection (Article 21) — object to processing based on legitimate interests, and to direct marketing, which we must stop immediately
- Freedom from solely automated decisions (Article 22) — as described above, we do not make any
- Withdraw consent at any time, where processing relies on it — including health notes and marketing. Withdrawal does not affect processing already carried out.
To exercise any right, email dpo@prismintegratedsecurity.solutions or use the contact page. We respond within one calendar month and there is no fee, though we may need to verify your identity first. Some rights are subject to legal exemptions — where one applies, we will explain it.
You also have the right to complain to the Information Commissioner’s Office: ico.org.uk/make-a-complaint, 0303 123 1113, or Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF. We would welcome the chance to resolve your concern first.
10. Cookies
This website sets strictly necessary cookies only — the session cookies that keep you signed in to the customer portal. Under PECR these need no consent, which is why you see no cookie banner.
We do not set analytics, advertising or social media cookies. Specifically:
- our visitor analytics (Vercel Web Analytics) are cookie-free and aggregate — no identifier is stored on your device and no profile of you is built
- there are no Google Analytics, Meta, LinkedIn or TikTok tags on this site
- no third party sets cookies through this site for its own purposes
You can block or delete cookies in your browser settings at any time; blocking the portal session cookie simply means you cannot stay signed in. If we ever introduce cookies that require consent, we will add a consent mechanism and update this policy before they are set.
11. CCTV installed at your property
Where we install a CCTV system at your property, you are the data controller for the footage it captures — not Prism — and you have your own obligations under UK GDPR: display clear signage, limit retention (we recommend 31 days by default), store footage securely, and respond within one month to access requests from people who appear in it. The ICO’s video surveillance guidance explains these duties.
During installation, commissioning and maintenance our engineers may view live or recorded footage solely for testing and diagnosis. We do not copy, retain or store footage from customer systems, and any remote access for fault diagnosis is logged and limited to the minimum necessary. Ajax systems we install use end-to-end encryption; alarm verification images sent to EMCS are processed only to verify activations, and data in the Ajax Cloud is governed by Ajax’s own privacy policy.
12. Children
Our website and services are not directed at children under 13 and we do not knowingly collect their data. MediCare systems are arranged by adults on behalf of the person they care for. If you believe a child has given us personal data, contact dpo@prismintegratedsecurity.solutions and we will delete it.
13. Changes to this notice
We review this notice regularly and update it when our practices, the law or ICO guidance change. Material changes affecting existing customers will be emailed at least 14 days before they take effect. The date at the top is the date of the current version.